“…However, PLWE is more suitable for efficient implementations thanks to very fast multiplication algorithms like Toom, Karatsuba or versions of the Number Theoretic Transform (NTT) which are not available for number fields, where just finding integral bases becomes cumbersome even for moderately large degree and discriminant (let alone those of cryptographic size). Luckily, in a good number of interesting cases both problems are equivalent (see [2,3,5,6,13,14,15]).…”